Check Point Research tracked a long-running Operation Dream Job campaign linked to Lazarus, with a latest wave targeting defense organizations in Europe and India using trojanized PDF viewers, spear-phishing, and compromised web infrastructure. The campaign deployed SecurityPDF, Troy, MISTPEN, RelayShell, and a new FudModule variant exploiting CVE-2026-68820 while also abusing Roundcube servers via CVE-2025-49113. #OperationDreamJob #Lazarus #SecurityPDF #Troy #MISTPEN #RelayShell #FudModule #CVE-2026-68820 #CVE-2025-49113
Keypoints
- Operation Dream Job is an ongoing Lazarus campaign targeting organizations worldwide, with a strong focus on the defense sector.
- The latest wave emphasized defense, aerospace, and aviation victims in Europe, India, and other regions.
- Attackers used spear-phishing, impersonation websites, and SEO to distribute trojanized PDF viewers and malicious PDFs.
- Two infection chains were observed: a DLL sideloading chain using MISTPEN and a trojanized PDF viewer chain using SecurityPDF and the Troy backdoor.
- MISTPEN used Microsoft Graph API and OneDrive for in-memory payload delivery, reconnaissance, persistence, screenshot capture, and privilege escalation.
- Lazarus deployed a new FudModule variant exploiting CVE-2026-68820 in AFD.sys to gain SYSTEM privileges and disable EDR visibility.
- The group also abused compromised Roundcube, WordPress, and PrestaShop servers to host RelayShell and support command-and-control relays.
MITRE Techniques
- [T1566.001] Spearphishing Attachment – Victims were lured with job offers and malicious files sent in phishing messages (‘targeted spear-phishing lures centered on attractive job opportunities’).
- [T1036] Masquerading – The operators impersonated recruiters, Enveil, and legitimate PDF software to make malicious files appear trustworthy (‘posing as recruiters’; ‘impersonating Enveil’).
- [T1328] Spam / Search Engine Optimization Poisoning – Malicious download sites were boosted in search results to increase credibility (‘search engine optimization (SEO) techniques’).
- [T1574.001] DLL Search Order Hijacking / DLL Sideloading – A legitimate signed executable loaded a malicious DLL to execute payloads (‘loaded via DLL sideloading’).
- [T1027] Obfuscated Files or Information – Payloads and webshell data were encrypted, XORed, Base64-encoded, or otherwise obscured (‘encrypted zip archive’; ‘single-byte XOR key (0x39)’).
- [T1106] Native API – The malware used Windows APIs and low-level system interfaces for desktop capture and exploit execution (‘uses standard Windows USER32 and GDI APIs’; ‘invokes NtSetSystemInformation’).
- [T1055] Process Injection – FudModule injected a payload into a SYSTEM process and Troy performed reflective DLL injection (‘injects a payload into a SYSTEM process’; ‘reflective DLL injection’).
- [T1105] Ingress Tool Transfer – MISTPEN retrieved additional modules from OneDrive and RelayShell transferred data through files (‘retrieve additional modules’; ‘file-based communication channel’).
- [T1056.001] Keylogging / Input Capture? Not mentioned – No reliable evidence of this technique appears in the article; omitted.
- [T1082] System Information Discovery – Multiple modules collected host, OS, user, and process details (‘collects system and process information’; ‘collects basic system information’).
- [T1057] Process Discovery – PvPlugin enumerated running processes and collected PID/PPID data (‘collecting detailed information about running processes’).
- [T1113] Screen Capture – OneScreenCapture captured the desktop and returned it for exfiltration (‘capturing the current desktop’).
- [T1547.001] Registry Run Keys / Startup Folder – MISTPEN installed persistence to ensure execution after reboot (‘ensures that MISTPEN is automatically executed after system reboot’).
- [T1068] Exploitation for Privilege Escalation – The attackers exploited CVE-2026-68820 in AFD.sys to gain SYSTEM privileges (‘exploit the zero day vulnerability CVE-2026-68820’).
- [T1003] OS Credential Dumping – Not mentioned – The article does not describe credential dumping; omitted.
- [T1071.001] Web Protocols – Command-and-control traffic used HTTP to communicate with servers and relays (‘establishing an HTTP connection’; ‘web shell’).
- [T1090] Proxy – RelayShell turned compromised servers into relay nodes between victim and operator (‘repurposes compromised web servers as relay nodes’).
- [T1021] Remote Services – Troy supported remote access and command execution over C2 (‘providing a broad range of remote access’).
- [T1195] Supply Chain Compromise – Not mentioned – the campaign did not rely on supply-chain compromise; omitted.
- [T1102] Web Service – MISTPEN used Microsoft Graph API and OneDrive as a communications channel (‘uses Microsoft Graph API to access OneDrive’).
- [T1133] External Remote Services – Attackers accessed RelayShell through shared VPN services (‘accessing RelayShell through shared VPN services, including ExpressVPN’).
Indicators of Compromise
- [File hashes ] Malware and loader samples – 2b4987c07a3d9a9a5d1a9bf4efa3d1903e775090b611710edafdc92874265ca83a02d0d798e8d35555776886d92b20ff38a101c9ef7e0eebc8ce5d259516525a92106b0c62a0a42678232f8273f030b2d3c8e92efce81b98b9eec70cfe98afa1396192d92d17ace1a521f1351eeeba2825e60badd0d799cc5c338e4934b3c82cf7e620134ca935067797ab957317b346ce0df84a4e9b9ca54a6acc9b75afda4d75b93a7103b0562f6497d30052c0c5cf7aa58c1bf0e9297022b74469a7f096f1a45144d22cac70a45d71cf4dffa4efbc373658779a56cf1300d6ac863d6cc7e21de949c71efcfb0ffc41f33d38833dbc4b082075b1a540fc68c18c535d7ad86c4c9b804d6155b29f1e27a9ffe531e10bc42a7bdab42f905b50146bf2026768d929e24c007549e51319ff3aee011da6f9f93568e8c85a5ad69c9e53bd3f4533a24ebdce2f47c23ff8c9e8e80c8b5239c7a5764da31cd3ab8f0505926890adc105c2aa28bb5e2a749c693712008276f311edd912f689371ef9e8a1ee5fb4167461, 2db25ac41a66aa523c79e23e00443573530dd7bd82b8371bcc87bd7232e141eb5278ee922838352f1480a73e971161017d643a80b7ec22bf725897dfd088696db4082d21070d9ddf53fde4ea22524d09e41ec9826ce63cef3c6235e458d21afbfb3fc5626f68677fb1269a2fefbe70e719211b4065e836ab92e06a8210139a2dea7056f2bf36c66a61ff787ff5be975a85f534c3c5ca178791dac2504db2c61913d10bc99f7f7abe7ee0902be87920b73b2ea41bd9683dbfcad340dacbcdef794fd32432341dfcf54d0517a6bbc38e5d265be70933493e4183c2a340cdde9a2d4dd792c9f672bbdcc8d363d745994efe90f4ffc5fdc2c059c8e379a48ad6a68aba96c603e44046de703c67b2c3b7e4ca974afef7b437a0244418bc4edc781bb7, and 3 more hashes.
- [File hashes ] Additional malware samples – 72dccae85e062f541fecad9ec7a18a3123e7ae5ac5d53c91709b53a46dbbd289231b1ef8b95bf77887d5377e2a60f649035e78f543af1b82877db36a5759d8586da9b1e6f3315ceb77dd14a937a26cc3602bf6a7e2c2ecafb3c65ce5319837bea0578a2b7821d7e2c573530648f26d7a0d98b373ab24fb7f0c792736761e542d82268052f94df6f4870d02e57b18d4c54136cc7a8c8d80ad162631f99462c943, 3b6378df8442e63a6ed7317075913e4720847a510d95022d4a8347b2637c245d, and other related sample hashes.
- [Domain ] SecurityPDF and Troy infrastructure – envell[.]xyzenveil[.]online, uxtramine[.]org, and other impersonation or C2 domains.
- [IP addresses ] SecurityPDF and Troy infrastructure – 135.181.67[.]203, 135.181.185[.]158.
- [File names ] Malware components and payloads – SecurityPDF.exe, new.exe, libmupdf.dll, Afd4Eop12_x64.dll, and RelayShell.
- [YARA string / webshell markers ] RelayShell identification – ‘PqCWom’, ‘a84038’, ‘biwbih’, ‘ddf7acea’, ‘enRU904U’, and other embedded strings from the detected webshell.
- [Registry / system artifact ] Exploit and payload details – This document is encrypted with sumatrapdf reader!!!!!!!!!!!!, %TEMP%new.exe, and export DestroyEnv.